Логотип exploitDog
Консоль
Логотип exploitDog

exploitDog

redhat логотип

CVE-2026-15779

Опубликовано: 14 июл. 2026
Источник: redhat
CVSS3: 6.1
EPSS Низкий

Описание

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

Отчет

Red Hat Product Security rates this flaw's impact as Moderate. Exploitation requires mkhomedir to be explicitly enabled in pam_winbind.conf, a non-default option used specifically in Active Directory domain-integration deployments, and a PAM session to be opened for an account whose home directory resolves to /. While the most direct trigger is root running su to such an account, a non-root user holding a narrow sudo delegation to run a command as that account can reach the same code path. The resulting impact is denial of service through broken ownership checks affecting SSH, sudo, and package management, not privilege escalation: Red Hat Enterprise Linux ships / with restrictive 0555 permissions, so the new unprivileged owner is not granted write access to the filesystem root. Red Hat Enterprise Linux 9.9 and 10.3 are not affected, as an unrelated upstream refactor changed the home-directory-creation logic so ownership is only changed when a new directory is actually created rather than when the target already exists.

Меры по смягчению последствий

Do not enable mkhomedir in pam_winbind.conf on systems where any account (including system accounts) may resolve to a home directory of / or another sensitive system path.

Затронутые пакеты

ПлатформаПакетСостояниеРекомендацияРелиз
Red Hat Enterprise Linux 10samba-winbindAffected
Red Hat Enterprise Linux 6samba-winbindOut of support scope
Red Hat Enterprise Linux 7samba-winbindWill not fix
Red Hat Enterprise Linux 8samba-winbindAffected
Red Hat Enterprise Linux 9samba-winbindAffected

Показывать по

Дополнительная информация

Статус:

Moderate
Дефект:
CWE-732
https://bugzilla.redhat.com/show_bug.cgi?id=2499991samba-winbind: samba: pam_winbind mkhomedir chowns critical system paths without validation

EPSS

Процентиль: 1%
0.00104
Низкий

6.1 Medium

CVSS3

Связанные уязвимости

CVSS3: 6.1
ubuntu
около 1 месяца назад

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

CVSS3: 6.1
nvd
около 1 месяца назад

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

CVSS3: 6.1
debian
около 1 месяца назад

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pa ...

CVSS3: 6.1
github
около 1 месяца назад

A flaw was found in samba's pam_winbind. When mkhomedir is enabled, pam_winbind chowns the target account's home directory without validating the path is not a critical system directory such as /. On affected systems, accounts with / as their home directory (a common default for system accounts) can have this triggered not only by root, but by a non-root user holding a narrow sudo delegation to run commands as that account, causing ownership of / to change and resulting in severe denial of service (SSH, sudo, and package-manager failures). The change does not grant write access to / (which ships with restrictive 0555 permissions on RHEL), so the impact is availability loss rather than further privilege escalation.

suse-cvrf
20 дней назад

Security update for samba

EPSS

Процентиль: 1%
0.00104
Низкий

6.1 Medium

CVSS3